Privacy Policy

Last updated: 11 September 2026

This Privacy Policy explains how Kreativdistrikt SRL (“we”, “us”, “our”) collects, uses, and protects your personal data when you use our website or services. It also explains your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR).

For details of the specific cookies used on this website, please see our Cookie Policy.


1. Data Controller

Kreativdistrikt SRL is the Data Controller of your personal data.

Kreativdistrikt SRL Via Petrarca 22 20123 Milan Italy Email: info@kreativdistrikt.com

We operate worldwide, except in embargoed countries.


2. Services

We provide innovation and creative services, including the organisation of hackathons, ideathons, and similar events, both online and offline.

Our website (https://www.kreativdistrikt.com/) provides information about our services and allows users to contact us and book consultations.

No user accounts are required to use our website.


3. Personal Data We Collect

We may collect the following categories of personal data.

3.1 Data provided directly by you

  • Name
  • Email address
  • Phone number
  • Company name
  • Message content (contact forms or inquiries)
  • CVs and application materials (event participation)
  • Participant data provided during events

3.2 Event-related data

When you participate in our events, we may also process:

  • Attendance records
  • Submitted projects or materials
  • Event-related communications
  • Work produced during events
  • Intellectual property-related information relevant to the event terms

3.3 Media data

  • Photographs and video recordings taken during events (where applicable)

3.4 Technical data collected automatically

  • IP address
  • Browser type and version, device type, operating system
  • Pages visited, time spent, referring website
  • Interaction data such as clicks and scrolling (where you have consented to analytics or marketing cookies)

4. How We Collect Data

We collect data:

  • Directly from you (forms, applications, event participation)
  • Automatically via website analytics and security tools
  • Through third-party event platforms used to manage events

We use third-party platforms such as HackSquad (or equivalent event management systems) to facilitate event participation and operations.


5. Legal Basis for Processing

We process personal data in accordance with the legal bases provided under Article 6 of the GDPR. Depending on the specific context, the legal bases include:

Performance of a contract (Art. 6(1)(b) GDPR) When processing is necessary for the performance of a contract with you or to take steps before entering into a contract. This includes managing event participation, delivering services, and processing related requests.

Consent (Art. 6(1)(a) GDPR) When you have given clear consent for us to process your personal data for specific purposes, such as the use of photographs or video recordings for promotional purposes, or the use of non-essential cookies and similar tracking technologies.

Legitimate interests (Art. 6(1)(f) GDPR) When processing is necessary for our legitimate interests, provided that such interests are not overridden by your fundamental rights and freedoms. This includes website security, prevention of fraud or misuse, and service improvement.

Legal obligation (Art. 6(1)(c) GDPR) When processing is necessary to comply with applicable legal obligations, including accounting, tax, and regulatory requirements.

Where processing is based on legitimate interests, you have the right to object to such processing at any time.


6. Use of Personal Data

We use personal data for the following purposes:

  • Providing and managing our services
  • Organising and administering events
  • Processing event applications and participation
  • Communicating with users
  • Managing inquiries submitted through the website
  • Improving our services and operations
  • Marketing and promotional activities (where consent applies)
  • Documenting events (including photos and videos, where applicable)
  • Managing business relationships and contracts
  • Protecting the security and integrity of our website

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, and in accordance with applicable legal and contractual obligations.

Category of data Retention period
Contact form submissions and inquiries 24 months from last contact
Event participant data Duration of the event plus 24 months
CVs and application materials 12 months from the end of the selection process
Accounting and invoicing records 10 years, as required by Art. 2220 of the Italian Civil Code
Analytics data 14 months
Security logs, including IP addresses 6 months
Photographs and video recordings Until consent is withdrawn
Cookie consent preferences 12 months, after which consent is requested again

Where data is no longer required, it is deleted or irreversibly anonymised.


8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate and improve our website.

Cookies are grouped into the following categories:

  • Necessary cookies — required for the website to function. These do not require consent.
  • Functional cookies — enable features such as appointment booking.
  • Statistics cookies — measure website performance and visitor behaviour.
  • Marketing cookies — support advertising and audience targeting.

Non-essential cookies are blocked until you give consent through our consent banner. You can change or withdraw your preferences at any time using the “Manage consent” option on any page.

A complete and regularly updated list of the individual cookies used on this website, including their purpose and duration, is available in our Cookie Policy.


9. Third-Party Services

We use third-party service providers to support the operation of our website and the organisation of our services and events. These third parties may process personal data on our behalf, or in some cases as independent data controllers.

9.1 Analytics and advertising

Service Provider Purpose
Google Analytics 4 Google Ireland Ltd Website usage measurement
Google Tag Manager Google Ireland Ltd Management of tracking scripts
Google Ads Google Ireland Ltd Advertising and conversion measurement
Meta Pixel and Meta Conversions API Meta Platforms Ireland Ltd Advertising, audience targeting, and conversion measurement, including server-side event transmission
LinkedIn Insight Tag LinkedIn Ireland Unlimited Company Advertising and conversion measurement
Hotjar Hotjar Ltd (Malta) Behaviour analytics, including heatmaps and session recordings

9.2 Website functionality

Service Provider Purpose
Calendly Calendly LLC (USA) Appointment scheduling
YouTube Google Ireland Ltd Embedded video content
Google Fonts Google Ireland Ltd Website typography
Contact Form 7 and Redirection for Contact Form 7 Self-hosted Contact form handling; submissions are stored in our website database
Email marketing connector (Mailchimp) Respective provider Transfer of newsletter sign-ups where you have opted in
FluentSMTP Self-hosted Transmission of outgoing email
WP Rocket and RocketCDN WP Media SAS (France) Performance optimisation and content delivery
Imagify WP Media SAS (France) Image optimisation

9.3 Security

These services process IP addresses to protect the website against unauthorised access and malicious activity. The legal basis is our legitimate interest in website security (Art. 6(1)(f) GDPR).

Service Provider Purpose
Wordfence Defiant Inc (USA) Firewall, malware scanning, IP logging
Really Simple Security Really Simple Plugins BV (Netherlands) Website hardening, login protection, IP logging
Limit Login Attempts Reloaded Progress Planner BV Brute-force protection, IP logging

9.4 Infrastructure and operations

Service Provider Purpose
Website hosting GoDaddy Hosting and infrastructure
Google Workspace Google Ireland Ltd Email and internal collaboration
HackSquad or equivalent Respective provider Event management and participation

Where these providers act as data processors, they process personal data strictly in accordance with our instructions and applicable data processing agreements. Where they act as independent controllers, their processing is governed by their own privacy policies, which we encourage you to review.


10. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including countries that may not provide the same level of data protection as within the EEA.

This may occur in connection with our use of service providers and platforms such as hosting providers, analytics services, marketing tools, and event management systems.

Where such transfers take place, we ensure that appropriate safeguards are implemented in accordance with the GDPR. These safeguards may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Reliance on adequacy decisions issued by the European Commission, including the EU-US Data Privacy Framework where the recipient is certified
  • Appropriate technical and organisational security measures

11. CVs, Applications, and Project / Intellectual Property Data

When you apply to participate in our events or submit materials such as CVs, applications, or project-related content, we process your personal data for:

  • Evaluating applications and determining eligibility for participation in events
  • Managing event organisation and participation
  • Facilitating collaboration and execution of event-related activities
  • Communicating with participants in relation to the event

CVs and application materials are processed solely for evaluation and selection purposes related to the relevant event.

Project submissions and related materials may be processed in the context of your participation in our events and in accordance with the applicable event terms. This may include information related to intellectual property rights, ownership, or usage of submitted work, as defined in the relevant contractual or event-specific documentation.

Retention periods for this category are set out in Section 7.


12. Photos and Event Media

During the organisation and execution of our events, we may collect and process photographs, video recordings, and similar media content.

This processing is carried out for:

  • Documenting our events and activities
  • Communicating and reporting on our services
  • Promoting our events and organisation through appropriate channels, including our website and social media platforms

Legal basis:

  • Consent (Art. 6(1)(a) GDPR) for identifiable photography and video used for promotional purposes
  • Legitimate interest (Art. 6(1)(f) GDPR) for general event documentation in which individuals are not the focus of the image

Where processing is based on legitimate interest, you have the right to object to the use of your personal data, including images or recordings, at any time by contacting us at info@kreativdistrikt.com.

We take reasonable measures to ensure that such content is used responsibly and in a manner that respects your privacy. Retention periods are set out in Section 7.


13. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal

To exercise any of these rights, contact us at info@kreativdistrikt.com. We will respond within one month, as required by Art. 12(3) GDPR.

You also have the right to lodge a complaint with the supervisory authority in Italy:

Garante per la Protezione dei Dati Personali Piazza Venezia 11, 00187 Roma www.garanteprivacy.it


14. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted connections (HTTPS), access controls, firewall protection, and monitoring for malicious activity.

However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.


15. Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect or process personal data from minors.

If we become aware that personal data has been collected from an individual under the applicable minimum age without appropriate authorisation, we will take reasonable steps to delete such data promptly.

If parental consent is required under applicable law, we may request verification of such consent before processing any personal data relating to minors.


16. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be published on this page, and the “Last updated” date at the top will be modified accordingly.


17. Contact

For any questions regarding this Privacy Policy, you can contact us at:

Email: info@kreativdistrikt.com

Kreativdistrikt SRL, Via Petrarca 22, 20123 Milan, Italy